bootstrap-prelude
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes and modifies repository source code, which creates a potential surface for indirect prompt injection if those files contain malicious instructions.\n
- Ingestion points: Reads source code, manifests, and TypeScript configurations from the repository during the mapping phase (Step 1).\n
- Boundary markers: Instructions do not define specific delimiters to prevent the agent from interpreting data within the files as new instructions.\n
- Capability inventory: The skill has the ability to write to files and execute repository-defined verification commands such as formatters, linters, and tests (Step 5).\n
- Sanitization: No sanitization or safety checks are performed on the content read from the repository.
Audit Metadata